PT-2026-83776 · Valkey Io · Valkey

·

CVE-2026-82677

·

Published

2026-08-31

·

Updated

2026-09-01

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions valkey-io valkey version 9.1.0
Description A double free issue exists in the Module Timer Subsystem within the moduleTimerHandler() function located in the src/module.c file. This flaw allows a remote attacker to trigger a double free, which occurs when the system attempts to free the same memory location twice, potentially leading to a crash or arbitrary code execution.
Recommendations Deploy patch b349fe2821e3998534b1454c1b64a478daf8c6b7 for version 9.1.0.

Exploit

Fix

Buffer Overflow

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82677

Affected Products

Valkey